VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

28783 CVEsRSS

CVE-2026-74926High· 7.1
2w ago

The MultiVendorX WordPress plugin before 5.0.16 does not verify that a user owns the store they are acting on in one of its REST API routes, allowing any authenticated user, such as a subscriber, to overwrite any store's details and pay…

The MultiVendorX WordPress plugin before 5.0.16 does not verify that a user owns the store they are acting on in one of its REST API routes, allowing any authenticated user, such as a subscriber, to overwrite any store's details and pay…

▾ TwilightEPSS 0.34%via NVD
CVE-2026-61396None
2w ago

Rejected reason: Did not need CVE ID

Rejected reason: Did not need CVE ID

▾ Sunlitvia NVD
CVE-2026-89063High· 7.5PoC
2w ago

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 28.1 via the 'conversation_id' parameter due to missing validation…

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 28.1 via the 'conversation_id' parameter due to missing validation…

▾ Midnightladela · Online Scheduling and Appointment Booking System – BooklyEPSS 1.6%via NVD
CVE-2026-5920Medium· 6.4
2w ago

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shortcode_content' parameter of the bt_bb_shortcode shortcode in all versions up to, and including, 5.9.6

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shortcode_content' parameter of the bt_bb_shortcode shortcode in all versions up to, and including, 5.9.6. This is due to a bypassable secur…

▾ Sunlitboldthemes · Bold Page BuilderEPSS 0.28%via NVD
CVE-2026-18555Medium· 6.1
2w ago

The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'icn' parameter in all versions up to, and including, 2.15.22 due to insufficient …

The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'icn' parameter in all versions up to, and including, 2.15.22 due to insufficient …

▾ Sunlitwordplus · Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat BotsEPSS 0.23%via NVD
CVE-2026-14349Critical· 9.8
2w ago

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized …

▾ Midnightthemetechmount · TrueBooker – Appointment Booking and Scheduler SystemEPSS 0.42%via NVD
CVE-2026-16588Medium· 6.5
2w ago

The WP Directory Kit plugin for WordPress is vulnerable to blind SQL Injection via the 'order_by' parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient pr…

The WP Directory Kit plugin for WordPress is vulnerable to blind SQL Injection via the 'order_by' parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient pr…

▾ Sunlitwpdirectorykit · WP Directory KitEPSS 0.29%via NVD
CVE-2026-11984Medium· 5.3
2w ago

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.16 due to a missing capability check on the `ai-debug-code` URL-parameter

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.16 due to a missing capability check on the `ai-debug-code` URL-parameter. This makes it poss…

▾ Sunlitspacetime · Ad Inserter – Ad Manager & AdSense AdsEPSS 0.29%via NVD
CVE-2026-78088High· 8.8
2w ago

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Overwrite in all versions up to, and including, 32.0.1 due to insufficient file path valida…

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Overwrite in all versions up to, and including, 32.0.1 due to insufficient file path valida…

▾ Twilightcontest-gallery · Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & StripeEPSS 0.79%via NVD
CVE-2026-18595High· 7.2
2w ago

The WP-Lister Lite for eBay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via AJAX Cron Handler Request Parameter in all versions up to, and including, 3.8.9 due to insufficient input sanitization and output escaping.…

The WP-Lister Lite for eBay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via AJAX Cron Handler Request Parameter in all versions up to, and including, 3.8.9 due to insufficient input sanitization and output escaping.…

▾ Twilightwp-lab · WP-Lister Lite for eBayEPSS 0.25%via NVD
CVE-2026-12793Critical· 9.8PoC
2w ago

The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.2

The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.2. This is due to the plugin not validating that a submitted form ID belongs to a JetFo…

▾ Abyssaljetmonsters · JetFormBuilder — Dynamic Blocks Form BuilderEPSS 0.52%via NVD
CVE-2026-92247Medium· 4.7PoC
2w ago

A security vulnerability has been detected in synaptikcms synaptik-cms up to 1.3.4.4

A security vulnerability has been detected in synaptikcms synaptik-cms up to 1.3.4.4. This affects the function rename of the file admin/file-manager.php of the component Admin File Manager. The manipulation leads to unrestricted upload.…

▾ Twilightsynaptikcms · synaptik-cmsEPSS 0.40%via NVD
CVE-2026-11996Medium· 6.4
2w ago

The Advanced Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Notification Button Link' Field in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping

The Advanced Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Notification Button Link' Field in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes…

▾ Sunlitcodesupplyco · Advanced PopupsEPSS 0.21%via NVD
CVE-2026-86109Medium· 6.6
2w ago

The VeloCloud Edge software update workflow may accept update bundles without properly validating their signatures because the workflow does not restrict the digest algorithm used for artifact verification

The VeloCloud Edge software update workflow may accept update bundles without properly validating their signatures because the workflow does not restrict the digest algorithm used for artifact verification. An attacker with either suffic…

▾ SunlitArista Networks · VeloCloud EdgeEPSS 0.24%via NVD
CVE-2026-86108High· 8.0
2w ago

Insufficient validation of inputs supplied through affected VeloCloud Edge management and configuration workflows may allow an authorized management request or configuration value to be interpreted as an operating-system command

Insufficient validation of inputs supplied through affected VeloCloud Edge management and configuration workflows may allow an authorized management request or configuration value to be interpreted as an operating-system command. Success…

▾ TwilightArista Networks · VeloCloud EdgeEPSS 0.61%via NVD
CVE-2026-92221Medium· 4.7PoC
2w ago

A vulnerability was determined in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8

A vulnerability was determined in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Affected by this vulnerability is the function generate_index_pasien of the file application/models/app_global_admin_model.p…

▾ Twilightgedelumbung · HospitalManagementEPSS 0.35%via NVD
CVE-2026-92220Medium· 5.3⚖ disputed
2w ago

A vulnerability was found in vllm-project vLLM 0.26.0/0.27.0

A vulnerability was found in vllm-project vLLM 0.26.0/0.27.0. Affected is the function MoRIIOConnectorScheduler.request_finished/MoRIIOConnectorWorker.get_finished/MoRIIOWrapper._handle_release_message of the file vllm/distributed/kv_tra…

▾ Sunlitvllm-project · vLLMEPSS 0.70%via NVD
CVE-2026-92299High· 7.4
2w ago

@jitsi/electron-sdk before 10.0.5 exposes getDesktopSources() via contextBridge without requiring an active getDisplayMedia() picker, allowing any script in the meeting page to enumerate screens and windows

@jitsi/electron-sdk before 10.0.5 exposes getDesktopSources() via contextBridge without requiring an active getDisplayMedia() picker, allowing any script in the meeting page to enumerate screens and windows. Attackers can call the jitsi-…

▾ TwilightJitsi · @jitsi/electron-sdkEPSS 0.48%via NVD
CVE-2026-92298Medium· 4.8
2w ago

EspoCRM through 10.0.8 uses PHP's rand() function to generate tokens for lead-capture opt-in, event invitation, and campaign URLs instead of a cryptographically secure generator

EspoCRM through 10.0.8 uses PHP's rand() function to generate tokens for lead-capture opt-in, event invitation, and campaign URLs instead of a cryptographically secure generator. Remote unauthenticated attackers can guess these roughly 3…

▾ SunlitEspoCRM · EspoCRMEPSS 0.43%via NVD
CVE-2026-73450Medium· 6.9
2w ago

On affected platforms running Arista EOS with MLAG Dual Primary Detection configured, an unauthenticated attacker with access to the Dual Primary Detection network segment can send specially crafted packets to interfere with the dual-pri…

On affected platforms running Arista EOS with MLAG Dual Primary Detection configured, an unauthenticated attacker with access to the Dual Primary Detection network segment can send specially crafted packets to interfere with the dual-pri…

▾ SunlitArista Networks · EOSEPSS 0.16%via NVD
CVE-2026-92217Medium· 6.3
2w ago

A vulnerability was determined in a2ui-project a2ui up to 0.10.6

A vulnerability was determined in a2ui-project a2ui up to 0.10.6. This affects the function processMessages of the file renderers/web_core/src/v0_9/processing/message-processor.ts of the component Message Parsing. This manipulation cause…

▾ Sunlita2ui-project · a2uiEPSS 0.43%via NVD
CVE-2026-92216Medium· 4.3
2w ago

A vulnerability was found in a2ui-project a2ui up to 0.10.7

A vulnerability was found in a2ui-project a2ui up to 0.10.7. Affected by this issue is the function openUrl of the file renderers/web_core/src/v0_9/rendering/generic-binder.ts of the component Binder. The manipulation results in open red…

▾ Sunlita2ui-project · a2uiEPSS 0.48%via NVD
CVE-2026-92214Low· 3.5
2w ago

A flaw has been found in a2ui-project a2ui up to 0.10.7

A flaw has been found in a2ui-project a2ui up to 0.10.7. Affected is an unknown function of the file samples/community/client/angular/projects/a2a-chat-canvas/src/lib/services/sanitizer-markdown-renderer-service.ts of the component a2a-c…

▾ Sunlita2ui-project · a2uiEPSS 0.35%via NVD
CVE-2026-92215High· 7.3
2w ago

A vulnerability has been found in a2ui-project a2ui up to 0.10.7

A vulnerability has been found in a2ui-project a2ui up to 0.10.7. Affected by this vulnerability is the function httpx.get of the file agent_sdks/python/a2ui_agent/src/a2ui/extensions/file_resolve/file_resolver.py of the component FileRe…

▾ Twilighta2ui-project · a2uiEPSS 0.51%via NVD
CVE-2026-92213Medium· 5.5
2w ago

A vulnerability was detected in a2ui-project a2ui up to 0.10.6

A vulnerability was detected in a2ui-project a2ui up to 0.10.6. This impacts the function z.any of the file renderers/web_core/src/v0_9/schema/server-to-client.ts of the component Angular Renderer. Performing a manipulation of the argume…

▾ Sunlita2ui-project · a2uiEPSS 0.32%via NVD
CVE-2026-73446High· 7.4
2w ago

On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit (PDU) that causes the device to tear down an established IS-IS adjacen…

On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit (PDU) that causes the device to tear down an established IS-IS adjacen…

▾ TwilightArista Networks · EOSEPSS 0.27%via NVD
CVE-2026-73459High· 7.4
2w ago

On affected platforms running Arista EOS with IS-IS configured, an unauthenticated attacker who can inject a specially crafted IS-IS LSP PDU can cause the legitimate LSP to be unexpectedly purged from the IS-IS link-state database

On affected platforms running Arista EOS with IS-IS configured, an unauthenticated attacker who can inject a specially crafted IS-IS LSP PDU can cause the legitimate LSP to be unexpectedly purged from the IS-IS link-state database. This …

▾ TwilightArista Networks · EOSEPSS 0.17%via NVD
CVE-2026-73460Medium· 6.1
2w ago

On affected platforms running Arista EOS with IS-IS graceful restart enabled, an unauthenticated attacker who can inject a malformed IS-IS LSP PDU packet can cause the IS-IS graceful restart procedure to terminate prematurely

On affected platforms running Arista EOS with IS-IS graceful restart enabled, an unauthenticated attacker who can inject a malformed IS-IS LSP PDU packet can cause the IS-IS graceful restart procedure to terminate prematurely. This may r…

▾ SunlitArista Networks · EOSEPSS 0.20%via NVD
CVE-2026-15638Critical· 9.1
2w ago

An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys

An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys. The key itself is not exposed.

▾ MidnightDelinea · Secret Server (On-Prem)EPSS 0.20%via NVD
CVE-2026-15640Critical· 9.5
2w ago

Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.

Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.

▾ MidnightDelinea · Secret Server (On-Prem)EPSS 0.28%via NVD
CVEs tagged “nvd” — page 238 · VulnSea